DNS Bug Testing Tools and Info

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

DNS Bug Testing Tools and Info

Post by Tami »

From [url=\"http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9110838&pageNumber=1\"]ComputerWorld[/url]:

[b]How do I know if I'm vulnerable?[/b] Several free online tools will tell you whether the DNS resolving server you use has been patched.

* [url=\"http://www.doxpara.com/\"]Kaminsky's blog[/url] has one. Click "Check My DNS" at the upper right under the "DNS Checker" heading.
* [url=\"https://www.dns-oarc.net/oarc/services/dnsentropy\"]DNS-OARC[/url] (DNS Operations, Analysis and Research Center) has a Web-based testing tool as well as instructions on using the Unix "dig" command.
* [url=\"http://www.dnsstuff.com/\"]DNSstuff.com[/url] also boasts a Web testing tool. Click "Test Now" in the box at the lower left of the home page; the box is tagged as "DNS Vulnerability Check."

[b]What do I do if I'm vulnerable?[/b] Patches are out, but as Kaminsky has said, this is really a problem for Internet service providers and companies -- which maintain DNS servers -- to fix, rather than an end-user issue.

But that doesn't mean there's nothing for you to do.

If the testing tools show that you're vulnerable, you should contact your ISP or network administrator to ask what is being done to plug the hole.

You should also apply any client-side patches that have been released. Microsoft Corp., for instance, rolled out fixes on July 8 for Windows 2000, XP, Server 2003 and Server 2008. If you haven't applied the update spelled out in [url=\"http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx\"]Security Bulletin MS08-037[/url], do so now.

According to a security advisory that Microsoft issued late last week -- after attack code geared to the DNS bug went public -- users who have installed the update are safe from attacks using the currently available exploits.

[b] I use a Mac. What do I do?[/b] Apple Inc. has not yet patched Mac OS X, a fact that hasn't escaped security researchers such as Andrew Storms of nCircle Network Security Inc. and security consultants such as Rich Mogull.

As Mogull said in a story he wrote for TidBits last week: "Apple has not yet provided a patch, unlike dozens of other companies that make or distribute operating systems or DNS server software. Their customers are now in danger, and Apple needs to respond immediately."

Fortunately, noted Mogull, attacks are much more likely against Mac servers than individual Macs, so though the later are technically vulnerable, "there's no need to panic."

[b]If Your ISP Hasn't Patched Their DNS:[/b]

You can shift to other DNS servers, in effect abandoning those run by your ISP.

Several prominent security experts, including Kaminsky, have recommended OpenDNS, a free service that includes detailed instructions on how to steer your browser to its servers for DNS lookups by modifying settings in your operating system or router.
~~~~~

Kaminsky's blog, [url=\"http://www.doxpara.com/\"]DoxPara Research[/url], is full of very good information, it might worth taking the time to read it.
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Wayne
Sr. Member
Sr. Member
Posts: 362
Joined: Thu Jun 17, 2004 12:37 am

DNS Bug Testing Tools and Info

Post by Wayne »

Of all the security problems and bugs in the past ... the one that this article relates to is by far the one that scares me the most. Your computer getting a virus or a Trojan is fixable, and so is keylogger password theft for most things, but this... This can take my banking info, divert my bill pay, and change all my accounts, take my money and leave no trace of it. THAT scares me.

<img src=\'http://www.killanet.net/forum3/public/s ... /ggsad.gif\' class=\'bbc_emoticon\' alt=\'(sad)\' />
Josh
Hero Member
Hero Member
Posts: 4627
Joined: Fri Jun 04, 2004 2:54 pm

DNS Bug Testing Tools and Info

Post by Josh »

If you are running Windows Vista, you have nothing to worry about.
[align=center]

Image

“If you stop learning, you stop living.” ~Tami Quiring

“It's the rare man who understands the value of a single perfect rose.”

[/align]
NightStorm
Administrator
Administrator
Posts: 778
Joined: Mon May 17, 2004 4:05 pm

DNS Bug Testing Tools and Info

Post by NightStorm »

Except that Wayne is a MAC user. <img src=\'http://www.killanet.net/forum3/public/s ... >/blum.gif\' class=\'bbc_emoticon\' alt=\':P\' />
For the record, our home ISP, as well as the DNS that all of our servers operate under, are not vulnerable to this exploit.

Go figure, huh? <img src=\'http://www.killanet.net/forum3/public/s ... igwink.gif\' class=\'bbc_emoticon\' alt=\';)\' />
[align=center]Image



[gamertag]NightStormDraco[/gamertag]

[twitter]NightStormDraco[/twitter]

[/align]
Post Reply

Return to “Security”